Note: This is an unofficial English translation provided for your convenience. The Turkish version is the legally binding text; in case of any discrepancy, the Turkish text prevails.
As LA Fish ("LA Fish"), we respect your privacy and treat the protection of your personal data as a priority
responsibility. This policy explains how we collect, process, and protect data when you visit our website or
use the LA Fish application.
This policy should be read together with the KVKK (Turkey's Personal Data Protection Law No. 6698)
Information Notice. For the official disclosure under the KVKK, please review the
KVKK Information Notice.
1. Information We Collect
1.1 When You Provide It to Us
- Account information: First and last name and email address during registration.
- Sign in with Apple / Sign in with Google: If you sign up or log in with one of these
methods, the provider (Apple Inc. or Google LLC) sends us your name (with Apple, only on your first sign-in
and only if you choose to share it), your email address (with Apple, a private relay address created by
Apple if you choose to hide your email) and the user identifier the provider assigns to you. This
information is used only to create your account and let you sign in; we never see your password with the
provider. When you delete your account, this information is deleted as well, and the link with Apple is
also removed on Apple's side.
- Billing information: When purchasing a subscription — first and last name, billing
address, tax ID number, or (only for individual e-invoicing) national ID number (TCKN), used as tax ID.
Credit card information is processed directly by the payment institution; LA Fish does not see or store
your full card number or CVC — only the token generated by the payment institution and the card's last 4
digits (for display purposes) are kept.
- Contact forms: Information you share in your support or contact requests.
- Service ratings (optional): When you rate a service you received: the provider's (company or
technician) name, phone or email, city, your rating and your review.
- Home and workplace address (optional): The home/workplace address you add in My Space;
details other than country, province and district (neighbourhood, street, building and flat number, postcode)
are stored encrypted. When you search for an address in My Space, the text you type is sent through our server to
Google LLC's address service to find suggestions; your name, email and IP address are not sent. When you use
Use My Location, your location is read once and converted to an address on your device; we do not store
it and it is not sent to our servers.
1.2 What We Collect Automatically
- Session data: Login IP address, session duration, device type, and operating system.
- Usage statistics: Which features are used, the number of receipts processed (a numeric
metric, not content).
- Optional usage statistics (mobile app only, with your permission): Daily totals about which
features are used, never linked to your account or device. See Section 1.3 below for details.
- Error and crash logs: Error/crash logs and diagnostic information generated to ensure
the stability and security of the application (via the error-tracking system on our own server). See
Section 1.4 below for details.
- Advertising data (Free tier only): Our advertising provider Google AdMob may collect
your device's advertising identifier (on iOS only if you allow it), your IP address, device and app
information, and your ad interactions. See section 5 below for details.
- Cookies: Please review our Cookie Policy for
details.
1.3 Optional Usage Statistics (Mobile App)
If you allow it, the mobile app sends events chosen from a fixed list about which features are used to our own
server in Istanbul (e.g. "a receipt was added" and how it was added: manually or by scanning; "an item or
document was added in My Space"; on first launch, whether the device language is Turkish, English or other).
Only the platform (iOS or Android) is sent along with the events. Your name, email address, phone number,
account, device or advertising ID, location, the time of the event, the app version, the device model and the
contents of your records (receipt and document contents, merchants, amounts, spending categories) are not
sent.
The server does not store individual events; it only increases daily totals. Your IP address is not written
to these counts and is not recorded for this purpose. At the end of each day the counts are turned into
aggregate tables and the raw counters are deleted; numbers smaller than five are never published in these
tables, and the tables are kept for 24 months. The data is counted only on this server; it is not shared with
third parties and is not used for advertising or sold. Like the app's other requests to our server, the
request passes through our content delivery and security provider Cloudflare (see Section 5.2 of the
KVKK Information Notice).
Permission is asked on first launch on the last step of the introduction with "Allow" and "Don't Allow"
options; no answer is preselected and no usage data is sent until you choose. If you were already using the app, the same question is shown
once after the update. You can change your choice at any time under Account > Data & Storage > Usage
Analytics. While it is off, no usage data is sent; the moment you turn it off, sending stops and events not yet
sent are deleted from the device. These statistics exist in version 1.1.2 and later of the mobile app; the
website and the desktop app do not send usage statistics.
1.4 Error Reports
When the mobile app crashes or hits an error, the error type and its technical details, the app version, the
device model and operating system information, and, when an error occurs on our server, the technical details
of that error, are sent to the error-tracking system running on our own server in Istanbul. Reports contain no
account information, email address or IP address; values such as session keys and passwords are masked before
sending. Reports are used only to find and fix errors and are deleted after 60 days. The mobile app's reports
also pass through Cloudflare.
Versions of the mobile app older than 1.1.2 may continue to send error reports to the error-tracking provider
Sentry (Functional Software, Inc.; EU, Frankfurt region) for a while; these reports are kept there for 90 days.
Once you update the app, reports go only to our own server.
2. How We Use Data
- To create, verify, and manage your account,
- To carry out subscription and payment transactions,
- To provide technical support,
- To ensure service security and integrity, and to find and fix errors using error reports,
- If you give permission, to identify the most-used features and solve problems using aggregate usage
statistics,
- To fulfill legal obligations,
- To send marketing messages if you give explicit consent,
- To show ads and measure ad delivery on the Free tier,
- To include subscription and product prices, without showing your identity or receipt details, in anonymous,
aggregated price comparisons built from at least 3 different users (e.g. a cheaper plan from the same provider),
- To use your service ratings, without showing your rating or review to anyone, only to recommend providers to
other users by name and contact details,
- When you ask, to research prices of your valuable items on stores' public product pages using brand and model
(no personal data is sent to stores).
3. Receipt Images and Document Content
Receipt/invoice images that you upload to the LA Fish application or scan through the application may
qualify as personal data. This data is processed as follows:
- Local reading (all plans): Reading takes place entirely on the user's device; the image is not
transmitted to the server for reading purposes. Unless you give explicit consent to the Cloud Receipt
Archive described below, your image is not stored on LA Fish systems.
- All plans – AI reading: The image is transmitted for processing to the Vertex AI
infrastructure (Gemini model) of Google Cloud EMEA Limited (Ireland) over a secure TLS channel; processing
takes place on servers in the EU (cross-border transfer). Inputs are not used for model training and are not
stored permanently by Google. Once
this temporary server-side processing is complete, the image is deleted from the server; unless you give
consent to store the image in the Cloud Receipt Archive described below, your image is not retained by
us.
- Cloud Receipt Archive (optional, subject to your explicit consent): If you give explicit
consent, the receipt fields that have been read (merchant name, date, time, receipt number, amount/tax
base/VAT, payment type, category) are permanently stored on our server in Turkey; your tax ID or national
ID number, if any, is kept encrypted, and, if you request it, the receipt image itself is also stored
encrypted (storing the receipt image is subject to your plan's quota). Your receipts are kept separated
according to the company/taxpayer you define. There is no cross-border transfer within this archive; the
data is kept only on the server in Turkey (this is separate and independent from the consent for
cross-border processing given for AI reading). Your data is retained until you withdraw your
consent, delete the relevant receipt, or delete your account. You may withdraw your consent at any time; in
that case, new receipts will not be archived. If you wish, you can turn on the "auto-delete oldest image"
preference so that the oldest receipt image is deleted once your quota is full (in this case the receipt
data is preserved and only the image is deleted). You can delete your receipts or images individually or
in bulk from the "My Receipts" screen; if you delete your account, the receipt data, images, and company
definitions in the archive are permanently deleted. When you request access to and portability of your
data, the archived receipts and company definitions are also exported. Legal basis: your explicit consent
under Article 5/1 of the KVKK.
Data within the receipt content (merchant name, amount, VAT) is recorded in the user database in structured
form; this data is kept only in association with the user's account.
Card statements (Add From Card Statement, all plans): When you upload your bank's PDF
statement or screenshots of the card transactions in your banking app in the mobile app, the statement,
including the bank name, the card's last 4 digits and the transaction lines on it, is sent to the same
processor as receipt reading, the Vertex AI infrastructure (Gemini model) of Google Cloud EMEA Limited
(Ireland); processing takes place on servers in the EU (transfer abroad). The purpose is automatic reading of
the transaction lines. Images and files are not used for model training and are not stored permanently by
Google. The statement file is not stored in LA Fish systems; the lines that are read stay as an encrypted draft
until you save them, and the draft is deleted once you save. The expenses you save are kept in your cloud
receipt archive on our server in Türkiye under the archive rules above. Your full card number is never stored; only the last 4 digits are used. Reading statements requires you to accept the current version of the
explicit consent text that covers card statements; consent you gave earlier remains valid for receipt
reading.
4. Who We Share Your Data With
We do not sell or rent your personal data to third parties. Data is shared only in the following cases:
- Service providers: Payment infrastructure, cloud storage (operating infrastructure),
email service provider, advertising (Google AdMob, Free tier only), address suggestions (Google, only when you search for an address). These parties process data only on behalf of LA Fish and in accordance with its
instructions.
- Legal obligation: Sharing with authorized authorities as required by court order,
administrative order, or legal regulations.
- Business transfer: With the acquiring party in the course of a company merger or
transfer; in this case, users are informed in advance.
Some of our service providers (e.g., email delivery, CDN/security, advertising, AI processing, address
suggestions; error tracking in versions of the mobile app older than 1.1.2) are located abroad. For the complete list of cross-border transfers and their legal safeguards, please see
Section 5.2 of the KVKK Information Notice.
5. Advertising
Ads are shown only on the Free tier, where the app occasionally shows full-screen ads. No ads are shown, and
the advertising service is not started in the app at all, on paid plans (Standard, Premium and Premium Office),
during the trial, or after the "Remove Ads" purchase. Ads are served through Google's advertising service AdMob.
- Data collected: To show ads, measure whether an ad was viewed or tapped, and prevent
fraudulent traffic, Google may collect your device's advertising identifier, your IP address, device
information such as device model and operating system, app information, and your ad interactions.
- Not shared: Your receipt and document contents, home/vehicle records, name, email address,
and payment information are not shared with the advertising provider.
- iOS: The advertising identifier (IDFA) is shared only if you grant the tracking permission
the app asks for. If you don't, ads are shown without the advertising identifier. You can withdraw the
permission at any time under Settings > Privacy & Security > Tracking.
- Android: Outside the European Economic Area, the United Kingdom, and Switzerland, the app asks
for your explicit permission to personalise ads; if you don't give it, ads are shown without personalisation. You can
change your decision at any time under Account > Data & Storage > Ads. The advertising ID is provided by
Google Play services. You can delete or reset it
under Settings > Google > Ads (or Settings > Privacy > Ads, depending on your Android version); once
deleted, it cannot be used for advertising.
- European Economic Area, United Kingdom, and Switzerland: In these regions, Google's consent form
is shown before any ad; ads are then personalised or served without personalisation according to your choice.
You can change your choice under Account > Data & Storage > Ads > Ad Privacy Options.
- How Google uses this data: policies.google.com/technologies/partner-sites
6. Security Measures
For the security of your data, we apply TLS 1.3 encrypted transmission; application-level AES-based
(Fernet) encryption for sensitive fields (e.g., national ID number, accounting access credentials, and
receipt images together with tax/national ID numbers in the cloud archive); access authorization controls;
and regular security assessments. That said, we note that no transmission over the internet or electronic
storage is 100% secure, and that we take reasonable precautions.
7. Children's Privacy
LA Fish services are not directed at individuals under the age of 18. We do not knowingly collect personal
data belonging to individuals under 18. If you become aware that such data exists in our systems, please
notify us at [email protected]; it will be deleted immediately.
8. Links to Other Sites
Our website may contain links to other websites. We are not responsible for the privacy practices of these
sites; we recommend that you review their own privacy policies.
9. Changes to This Policy
This policy may be updated over time. You will be notified of significant changes by email and/or an in-app
notification. The current text is always published on this page.
10. Contact
For questions about privacy, you may write to [email protected]
with the subject line "Privacy".
11. Data Controller / Legal Information
| Company | YCT Sağlık Hizmetleri Ltd. Şti. |
| Registration (MERSİS) | 0946056894600001 |
| Tax ID (VKN) | 9460568946 |
| Address | Alacaatlı Mah. Park Cad. No: 15/15, Çankaya / Ankara |
| Email | [email protected] |
| Phone | +90 546 233 77 87 |